Debian Security Advisory
DLA-267-1 unattended-upgrades -- LTS security update
- Date Reported:
- 02 Jul 2015
- Affected Packages:
- unattended-upgrades
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2015-1330.
- More information:
-
It was discovered that unattended-upgrades, a script for automatic installation of security upgrades, did not properly authenticate downloaded packages when the force-confold or force-confnew dpkg options were enabled via the DPkg::Options::* apt configuration.
We recommend that you upgrade your unattended-upgrades package.
For Debian 6
Squeeze
, these issues have been fixed in unattended-upgrades version 0.62.2+squeeze1Note: This DLA was originally was published as DLA-265-1, but due to an error that id was reused.